Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent origin spoofing of tab-modal dialogs, which allows remote attackers to conduct phishing attacks via a crafted web site.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Firefox | Mozilla | * | 19.0.2 (including) |
| Firefox | Mozilla | 19.0 (including) | 19.0 (including) |
| Firefox | Mozilla | 19.0.1 (including) | 19.0.1 (including) |
| Firefox | Ubuntu | devel | * |
| Firefox | Ubuntu | hardy | * |
| Firefox | Ubuntu | lucid | * |
| Firefox | Ubuntu | oneiric | * |
| Firefox | Ubuntu | precise | * |
| Firefox | Ubuntu | quantal | * |
| Firefox | Ubuntu | raring | * |
| Firefox | Ubuntu | saucy | * |
| Firefox | Ubuntu | upstream | * |
| Seamonkey | Ubuntu | hardy | * |
| Seamonkey | Ubuntu | lucid | * |
| Seamonkey | Ubuntu | oneiric | * |
| Seamonkey | Ubuntu | upstream | * |